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(54) Method for generating digital watermarks and for exchanging data containing digital 
watermarks 

(57) A method for generating digital watermarks 
and for exchanging data containing such watermarks is 
described. The system is based on an watermarking 
technique which is robust against image transformation 
techniques such as compression, rotation, translation, 
and scaling. It uses modulation of the magnitude com- 
ponents in Fourier space and adds/reads a template in 
the log polar transform of the magnitude components. 
The tenplate is used for analyzing scaling and rotation. 
In addition, the system applies ayptographic protocols 
and public key techniques for both, encoding the water- 
mark and transferring watermarked data. Preferably, an 
author (ICH) encodes the watermark using an asym- 
metric cryptographic key pair provided by a public key 
infrastructure (PKI) and registers the watermarked data 
at a trusted registration party (ICO) before transmitting 
the data to a receiving party (IB). The latter can use the 
public key infrastructure (PKI) for verifying authorship. 
Transmission between the parties uses data protection • 
provided by the cryptographic keys. 
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Description 

[0001] The present invention relates to a method for 
generating digital watermarks and for transmitting data 
containing digital watermarks according to the preamble 
of the Independent claims. 

[0002] Digital watermarking is a method for marking 
data sets, such as images, sound or video. A digital 
watermark consists of a slight modification of the data 

« set that does not affect the data set's usability but that 

can be detected using dedicated analysis software or 
apparatus. Watermarking can e.g. be used for marking 
authorship or ownership of a data set. 

» [0003] Digital watermarking can be seen as a funda- 

mentaliDroblem in digital communications (see e.g. I 
Cox, J. Killlan. T. Leighton. and T Shamoon. "Secure 
spread spectrum communication for multimedia", Tech- 
nical report. N.E.C. Research Institute. 1995). Early 
methods of encoding watermarks consisted of no more 
than Incrementing an image component to encode a 
binary 'V and decrementing to encode a '0* (G. Caronni 
"Assuring Ownership Rights for Digital Images" in H. H. 
Brueggemann and W. Gerhardt-HaecW, editors, Relia- 
ble IT Systems VIS '95, Vieweg Publishing Company, 
Germany. 1995). Tirkel et al. (A. Z. Tirkel, G. A. Rankin. 
R. G. van Schyndel. W. J. Ho. N. R. A. Mee, and C. F. 
Osborne, "Electronic watermark", in Dicta-93, pages 
666-672, Macquarie University, Sydney Decennber 
1993) and van Schyndel et al. (A. Z. Tirkel, R. G. van 
Schyndel, and C. F. Osborne, "a two-dimensional digital 
watermark", in ACCV'95. pages 378-383. University of 
Queensland. Brisbane. December 6-8 1995) have 
applied the properties of m-sequences to produce obliv- 
ious watermarks resistant to filtering, cropping and rea- 
sonably robust to cryptographic attack. Matsui and 
Tanaka (K. Matsui and K. Tanaka, "Video- Steganogra- 
phy : How to secretly embed a signature in a picture", in 
IMA Intellectual Property Project Proceedings, pages 
187-206. January 1994) have applied linear predictive 
coding for watermarking. Their approach to hiding a 
watermark is to make the watermark resemble quanti- 
zation noise. Tirkel and Osborne (see above) were the 
first to note the applicability of spread spectrum tech- 
niques to digital image watermarking. Since then there 

, has been an increasing use of spread spectrum In dig- 

ital watermarking. It has several advantageous features, 
such as cryptographic security (see Tirkel and Osborne, 
above), and is capable of achieving error free transmis- 
sion of the watermark near or at the limits given by the 

^ maximum channel capacity (J. Smith and B. Comiskey. 

"Modulation and information hiding in images", in Ross 
Anderson, editor, Proceedings of the First International 
Workshop in Information Hiding. Lecture Notes in Com- 
puter Science, pages 207-226, Cambridge. UK, 
May/June 1996. Springer). Fundamental information 
theoretic limits to reliable communication have been dis- 
cussed by some authors (see Smith and Comiskey, 
above). The shorter the payload of a watermark, the 



better are the chances of it being communicated relia- 
bly Spread spectrum is an example of a symmetric key 
cryptosystem (B. Schneier, "Applied Cryptography". 
Wiley 2nd edition, 1995). System security is based on 

5 proprietary knowledge of the keys (or pseudo random 
seeds) which are required to embed, extract or remove 
an image watermark. One provision in the use of a 
spread spectrum system is that it is important that the 
watermarking be non-invertible because only in this way 

10 can true ownership of the copyright material be resolved 
(S. Craver, N. Memon, B. Yeo, and M. Yeung, "Can invis- 
ible marks resolve rightful ownerships ?", IS&T/SPIE 
Electronic Imaging '97 : "Storage and Retrieval of Image 
and Video Databases", 1997). 6 Ruanaidh et al. (J. K. 

75 6 Ruanaidh. W. J. Dowling. and F. M. Boland. "Phase 
watermarking of images", IEEE International Confer- 
ence on Image Processing. Lausanne. Switzerland, 
September 1996) and Cox et al. (see above) have 
developed perceptually adaptive transform domain 

20 methods for watermarking. In contrast to previous 
approaches listed above the emphasis was on errA^ed- 
ding the watermark In the most significant components 
of an image. The general approach used in these 
papers is to divide the image into blocks. Each block is 

25 mapped into the transform domain using either the Dis- 
crete Cosine Transform (W. B. Pennebaker and J. L. 
Mitchell, "JPEG Still Image Compression Standard", 
Van Nostrand Reinhold, New York, 1993). the Had- 
amard Transform (W. G. Chambers. "Basics of Commu- 

30 nlcations and Coding". Oxford Science Publications- 
Clarendon Press Oxford, 1985) or the Daubechies 
Wavelet Transform (W.H. Press. S.A. Teukolsky, W.T. 
Vetterling, and B.P. Rannery, "Numerical Recipes in C", 
Cambridge University Press, second edition, 1992). 

35 Information has been embedded using the DCT (J. J. K. 
6 Ruanaidh, W. J. Dowling. and F M. Boland. "Water- 
marking digital images for copyright protection", IEEE 
Proceedings on Vision. Image and Signal Processing. 
143(4) :250-256. August 1996. based on the paper of 

40 the same title at the IEEE Conference on Image 
Processing and Its Applications, Edinburgh, July 1995) 
FFT magnitude, and phase. Wavelets (see refs. of Rua- 
naidh, Dowling and Boland, above). Linear Predictive 
Coding (see Matsui et al.. above) and fractals (R Dav- 

45 ern and M. Scott. "Fractal based image steganography", 
in Ross Anderson, ed., Proceedings of the First Interna- 
tional Workshop in Information Hiding. Lecture Notes in 
Connputer Science, pp. 279-294, CanrdDridge. UK, 
May/June 1996. Springer Verlag). 

50 [0004] The Industrial importance of digital watermark- 
ing has resulted in a number of products on the market, 
either based on spread spectrum techniques or addi- 
tional registration services. They include the Picture- 
marc system by Digimarc. SureSign (former FBI's 

55 Fingerprint) by HighWater Signum, IP2 system by Intel- 
lectual Protocols, the Argent system by Digital Informa- 
tion Commodities Exchange, the PixelTag system by 
the MIT Media Lab, the SysCop system from Zhao and 
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Koch by the Frauenhofer-lnstitirt fur Graphische Daten- 
verarbeitung (J. Zhao and E. Koch, "Embeciding robust 
labels into innages for copyright protection", Technical 
report, Fraunhofer Institute for Computer Graphics, 
Darmstadt, Germany 1994. J. Zhao, "A WWW Service 
To Embed And Prove Digital Copyright Watermarks", 
Proc. Of the European Conference on Multimedia Appli- 
cation, Services and Techniques. Louvain-La-Neuve, 
Belgium, May 1996). and the Tigermark system from 
NEC. 

[0005] The approach of Zhao and Koch, based on the 
JPEG image compression algorithm, proceeds by seg- 
menting the image into individual 8x8 blocks. Only 
eight coefficients occupying particular positions in the 8 
X 8 block of DCT coefficients can be marked. These 
comprise the low frequency components of the image 
block but exclude the mean value coefficient as well as 
the low frequencies. Three of the rennalning DCT coeffi- 
cients are selected using a pseudo random number 
generator to convey information. The resemblance of 
this technique to frequency hop spread spectrum com- 
munications is also mentioned and the blocks are 
placed at random positions in the image. A WWW regis- 
tration service has been proposed for a local registra- 
tion and a local watermarking, for a server registration 
and a server watermarking, and for a local watermark- 
ing and a server registration. 

[0006] J.-F. Delaigle at al. (J.-F Delaigle. J.-M. Bouc- 
queau, J.-J. Quisquater & B. Macq. "Digital Images pro- 
tection techniques in a broadcast framework: An 
overview", Laboratoire de Telecommunications et de 
T§l6d6ction. Universit6 Catholique de Louvain) have 
applied signature labelling techniques for the copyright 
protection of digital images. Their approach is based on 
an enhanced image format and generates a digital sig- 
nature label in front of the image. This signature label 
can be easily ovenvritten or destroyed. 
[0007] It is an objective of the present invention to pro- 
vide a system of the type mentioned initially that pro- 
vides a simple and secure way of generating and 
transmitting watermarked data. 
[0008] In one aspect of the invention, this object is 
achieved by using an asymmetric private and public key 
pair, as it is used in cryptography The original data set 
(cover data set. cover image) is watermarked, wherein 
the watermark is encoded using one or both of said 
keys. The watermarked data set (stego data set, stego 
image) is then transmitted to a second party, wherein 
the same keys are used for establishing a secure trans- 
mission between the parties. This simplifies the admin- 
istration of keys since the only keys required are the key 
pair mentioned above. In addition to this, because cryp- 
tographic keys are less prone to guessing attacks than 
simple passwords, the security of the watermark is 
irrproved. 

[0009] In a preferred embodiment, both parties use 
asymmetric key pairs and a key protocol for establishing 
a common key between them. 



[001 0] The party creating the watermark can embed a 
private as well as a public watermark in the data set. 
wherein the private watermark is derived from the pri- 
vate key the public watermark from the public key The 

5 public watermark can be detected by third parties while 
the private watermark can only be detected using pri- 
vate information. Preferably the private watermark is 
not derived from the private key directly but from a hash 
value of the same, such that the author of the water- 

10 rnark does not have to reveal his private key if the pri- 
vate watermark is to be verified. 
[001 1 ] In a further aspect of the invention, the author 
of the watermark is again provided with an asymmetric 
cryptographic key pair. He embeds a message together 

15 with its cryptographic signature in the watermark. When 
verifying this watermark, the presence of the signature 
increases reliability because it proves that the message 
was signed by the author. 

[001 2] In yet another aspect of the invention , the cover 
20 data set is provided with a digital watermark and then 
transmitted to a registration party that permanently 
stores at least a hash value, time information and origin 
of the stego data set. 

[0013] In another aspect of the invention, a template 
25 modulation pattern is added to the Fourier transform of 
an image that is to be provided with a watermark. For 
checking the watermark, the Fourier transform of the 
stego-image is calculated. From this Fourier transform, 
the log polar mapping transform is generated, which is 
30 then searched for the modulation pattern. Using the log 
polar transform of the Fourier transform has the advan- 
tage that scaling and rotation of the stego image are 
expressed in translations. This allows an easy search 
for rotation and scaling using cross-correlation tech- 
35 niques. 

[0014] In still another aspect of the invention, the 
inr^ge to be watermarked is divided into blocks and the 
magnitude conponents of the Fourier transform of each 
block is modulated using the same pattern. This method 

40 provides robustness against cropping of the stego- 
image because a cropping leads to a circular translation 
in each block. Preferably, the magnitude components of 
the Fourier transform are modulated, wherein the sign 
of the modulation should be derived from the phase 

45 components, thereby reducing interference between the 
image data and the watermark as explained in the fol- 
lowing disclosure. 

[0015] Further aspects, advantages and applications 
of the invention are described in the claims and the fbl- 
50 lowing description, which desCTiption makes reference 
to the figures. They show: 

Rg. 1 the parties involved in individual watermark 
protection. 

55 Fig. 2 the parties involved in watermark protection 
using registered cryptographic keys. 
Fig. 3 the parties involved in watermark protection 
using registered cryptographic keys and a registra- 
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tion party, 

Fig. 4 the steps taken for embedding a watermark. 

Fig. 5 the steps for generating the template. 

Fig. 6 the steps for reading a watermark. 

Fig. 7 the steps for reading the template. 

Fig. 8 the tiling of the watermark in a stego-image. 

and 

Fig. 9 the tiling of the watermark in a cropped 
stego-image. 

I. Terms and Symbols: 

[0016] Before describing a preferred method and 
apparatus according to the Invention, some key terms 
and symbols used in its description are explained in the 
following: 

" Imaoe ": An image In either digital or physical form 
which may constitute a still Image or a video frame. 
It can also refer other types of data, such as video 
and sound, In particular when being used within the 
context of the protection and owner authentication 
methods of section It of the disclosure. 
" Signal ": A signal in either digital or physical form. It 
may refer to one dimensional or multidimensional 
signals such as image and video. 
" Imaoe Copvrioht Holder (ICHr : A party (or a proc- 
ess acting on behalf of it) "owning" a digital image. 
This is the party that generates the watermarks. 
" Image Buver (IB) ": A party (or a process acting on 
behalf it) which obtains (e.g. by purchase) via elec- 
tronic means a specific image from the ICH. 
" Image Authentication Process (lAP) ": A process 
for verifying that the Image has been processed 
(generation, storage, retrieval, modification, trans- 
mission) before by the ICH. 

" Image Authentication Data (IAD) ": The authentica- 
tion data used In the lAR 

"Stego": Implies that an Image or data is marked 
(i.e. it has an IAD embedded in it). The stego image 
is also referred to as the stego data set. 
" Cover ": Implies that an image or data is unmarked 
(I.e. it has no IAD embedded in it). The cover image 
is also referred to as the cover data set. 
" Watermark ": The form the IAD takes when it Is in a 
form suitable for embedding In a signal. 
" Image Copyright Office (ICO) ": An organization (or 
a process which acting on behalf it) which registers 
ownership for a specific Image. Successful registra- 
tion Is based on a verification procedure, e.g. by 
checking the name and postal address of CH. Infor- 
mation how ownership was acquired, the title of the 
image, a description of the type of image (artistic, 
literary, musical, dramatic) and date and place of 
first publication. After successful registration a dig- 
ital copyright certificate can be generated. 
" Digital copyright certificate ": Digital copyright data 
which comprise the copyright certificate data and a 



digital signature. 

" Copyright Request Data (CRD) ": Copyright data 
which contains the stego image, the image ID of the 
cover image, a Universal Copyright Convention 

5 Notice, a Copyright Symlxjl, the term "Copyright", 

the year of the copyright, the name of the copyright 
holder, and the phrase "All Rights Reserved". 
" Copvrioht Certificate Data (CCD) ": Copyright data 
which contains at least an image ID, a hash value of 

10 the digital image, a time stamp, a Universal Copy- 
right Convention Notice, a Copyright Symbol, the 
term "Copyright", the year of the copyright, the 
name of the copyright holder, and the phrase "All 
Rights Reserved". 

15 " Digital signature ": A data string which has been 
generated by a digital signature generation trans- 
formation. 

" Digital signature generation transformation ": A 
method for producing a digital signature. 
20 " Digital signature verification transformation ": A 
method for verifying whether a digital signature is 
authentic or not. 

" Digital signature scheme ": A scheme based on 
asymmetric cryptographic techniques whose pri- 

25 vate transformation is used for the digital signature 
generation and whose public transformation is used 
for the digital signature verification. 
" Digital signatu re scheme with message recovery": 
A digital signature scheme for which a priori knowl- 

30 edge of the input data Is not required for the signa- 
ture verification transformation. 
" Digital signature scheme with appendix ": A digital 
signature scheme for which the input data Is 
required as Input to the digital signature verification 

35 transformation. 

" Asymmetric key pair ": A pair of related crypto- 
graphic keys where the private key defines the pri- 
vate transformation and the public key defines the 
public transformation. 

40 " Symmetric kev ": A ayptographic key used with a 
symmetric cryptographic technique and known only 
to a set of specified entitles. 
" Asymmetric kev agreement protocol ": A protocol 
whereby a shared symmetric key becomes avalla- 

45 ble to two parties for subsequent cryptographic use. 
The symmetric key is exchanged on the basis of a 
digital signature scheme with message recovery. 
The signed keys are encrypted with an asymmetric 
public key. 

50 " Public Kev Infrastructure (PKI) ": An organization 
(or processes which acts on behalf of it) which 
offers services for the generation, registration, cer- 
tification, distribution, validation, and revocation of a 
certificate associated with an asymmetric key pair. 

55 " Public watermark ": A watermark that can be 
detected using a publicly available key (or a hash 
value thereof). 

" Private watermark ": A watermark that can only be 
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detected using a secret key (or a hash value 
thereof). It is not possible for an unauthorized third 
party to overwrite or delete the private watermark 
without the cryptographic secret keying information. 
" Embedded authentication data ": The hidden IAD. 
" Payload ": The core of the hidden IAD in bit form 
without error control coding applied. 
" Image ID ": The following format scheme for a glo- 
bally unique ID: The first 3 bytes determine the ICO. 
the following 3 bytes determine the ICH ID defined 
by the ICO. Finally the ICH can freely assign last 4 
bytes for each one of his digital images. 
"Oblivious ": A watermarking technique which does 
not require the cover image for extracting the mark. 
In other words, only the stego image is required to 
extract the mark when using an oblivious marking 
scheme. 

' Template ": A hidden message encoded in the 
image. By detecting the template, the scaling 
(zooming) and rotation suffered by a stego-image 
can be determined. 

" Pseudo random seed ": A value used to initialize a 
pseudo rarxiom number generator. 

Symbols: 

[0017] 

H distinguished (unique) name of the Image Copy- 
right Holder H 

0 distinguished name of the Image Copyright 
Office O 

B distinguished name of the Image Buyer B 

1 distinguished name of the Public Key Infrastruc- 
ture 

Certn entity H's public key certificate from I 
Certo entity 0*s public key certificate from I 
Certe entity B's public key certificate from I 
(Px -Vx) the elliptic curve key pair, with a key size of 
at least 209 bits, of an entity with the distinguished 
name X. See Alfred J. Menezes. Paul C. Van Oor- 
schot, and Scott A. Vanstone. "Handbook of 
Applied Cryptography", CRC Press, 1996. ISBN 0- 
8493-8523-7 
CC a copyright certificate 
KS key size of the elliptic curve pair 
DSSMRg(X,Y,Z) an elliptic curve based digital sig- 
nature generation scheme with message recovery, 
where X denotes the private key, Y the input data to 
be signed, and Z the resulting signature. 
DSSMRv(X,Y.Z) an elliptic curve based digital sig- 
nature verification scheme with message recovery, 
where X denotes the public key, Y the input data, 
and Z the resulting output data. 
DSSAPg(X,YZ) an elliptic curve based digital sig- 
nature generation scheme with appendix, where X 
denotes the private key. Y the input data to be 
signed, and Z the resulting signature. 



DSSAPv(X.Y,Z) an elliptic curve based digital sig- 
nature verification scheme with appendix, where X 
denotes the public key, Y the input data, and Z the 
resulting output data. 
5 KxY a secret key for a symmetric cryptosystem 

shared between two entities with the distinguished 
name X and Y. 

KxY[Data] denotes the cipher text generated by a 
symmetric cryptosystem with plain text Data. 
10 ah a collision resistant hash function 

AKAP(X,YKxY.pSx .VSX. PCx. VCx.pSv. VSy, PCy. VCy) 

applied asymmetric key agreement protocol (see 
ISO/IEC 11 770-3, "Information technology-Security 
techniques-Key management. Part 3: mechanisms 

75 using asymmetric techniques") with entity X*s pri- 
vate signature key psx, entity X's public verification 
key vsx. entity X's private dedperment key pcx. 
entity X's public endpherment key vcxp entity Y's 
private signature key psy, entity Y's public verif ica- 

20 tion key vsy entity Y's private dedpherment key 
pCy, and entity Y's public encipherment key vcy 
between the entities with the distinguished name X 
and Y. After the protocol was successfully executed, 
the two entities have agreed on a Kxy 

25 OIAE(X.Y.CI, SI) the oblivious image owner authen- 
tication embedding algorithm with the seed X, the 
F)ayload Y, the cover image CI, and the resulting 
stego image SI. 

OIAV{X,SI,Y) the oblivious image owner authenti- 
30 cation detection algorithm with the seed X. the 
stego image SI, and the resulting payload Y) 
TVP time-variant parameter, such as a random 
number, a time-stamp, or a sequence number. 
II concatenation of two data elements in this order. 
35 CI Cover Image 
SI Stego Image 

11. Protection and owner authentication: 

40 [001 8] Depending on the proof-level to be provided for 
the protection, the prefen^ed embodiment of the appara- 
tus and method according to the invention provides 
three different levels of reliability, which are based on 
each other, namely: individual watermark protection. 

45 watermark protection with registered cryptographic 
keys, and watermark protection with an ICO on the 
basis of registered ayptographic keys. 
[001 9] The present method and apparatus is based on 
an image owner authentication technique, described 

50 below, which embeds and detects the IAD as the pay- 
load of a watermark. The applied image owner authen- 
tication technique is based on a perceptually adaptive 
spread spectrum technique which provides reliable 
means of embedding robust watermarks. Such a tech- 

55 nique will be discussed in section III. In addition, a 
spread spectrum techniques is a form of symmetric 
cryptosystem. In order to errtsed or extract a water- 
mark, it is necessary to know the exact values of the 



5 



9 



EP 0 905 967 A1 



10 



seed used to produce pseudo random sequences used 
to encode a watermark The seeds are considered to be 
cryptographic keys for watermark generation and verifi- 
cation. System security can therefore be based on pro- 
prietary knowledge of the keys and provide in addition 
the necessary security parameters needed for a secure 
communication (mutual authentication, Integrity, confi- 
dentiality, non-repudiation) in the trading process of dig- 
ital images. Because spread spectrum signals are 
statistically independent (and therefore virtually orthog- 
onal), the present method and apparatus encodes more 
than one watermark in an image at the same time, 
namely private watermarks and public watermarks. The 
public watermarks indicate that the image is copyright 
material and provide information on true ownership. At 
the same time there are secure private watermarks 
whose secrecy depends on the private key of the asym- 
metric key pair of the ICH. 

[0020] Since the system provides for the registration 
of the public key of the asymmetric key pair, the ICH can 
prove that he is the only person in the possession of the 
adequate private key of the asymmetric key pair and. 
therefore, the generator of the private watermarks. 
[0021 ] The system also provides the secure registra- 
tion (mutual authentication, integrity, confidentiality, 
non-repudiation) of watermark encoded images (data 
sets) at an ICO. The stego image is registered at the 
ICO and a digital copyright certificate is generated 
which is signed by the ICO. If an unauthorized third 
party has also encoded watermarks in the same image, 
conflicting claims in copyright disputes can be resolved. 
Examining the time stamps of the copyright certificate 
enables the secure identification of the legal owner: The 
earliest of the time stamps identifies the legal owner if 
no copyright revocation request has been applied. 
[0022] Watermark protection with registered crypto- 
graphic keys and the ICO based copyright protection 
are based on a PKI. The PKI issues on request public 
key certificates containing the public key of the party, 
the distinguished name of the party, and a time stamp. 
Every certificate is signed witii the PKI's private key and 
the trust is built on the validity of the authentic copy of 
the PKI's public key (we assume that the public key of 
the PKI is accessible, authentically distributed, and ver- 
ifiable by every party). 

[0023] In the following the three levels of the system 
are described. 

a) Individual watermark protection 

[0024] As shown in Fig, 1 , the apparatus for the indi- 
vidual copyright protection is partitioned into two proc- 
esses, namely the ICH witii the distinguished name H 
and the IB process with the distinguished name B, Sup- 
pose (psh.vsh) a"cJ (pcH, vCh) are the elliptic curve key 
pairs of H. (psq.vsb) and (pce. vcb) are the elliptic curve 
key pairs of B. Suppose H has an authentic copy of vsb, 
vcb and B has an authentic copy of vsh. vch before they 



start any communication. 

[0025] The following phases are applied by the proc- 
esses of the individual copyright protection apparatus: 



H retrieves the cover image CI, generates a unique 
image identifier IDci, stores IDci. and retrieves the key 
pair (psh.vSh). 

10 

Phase 2 (generating private watermark): 
[0026] 

75 1 . H generates a private IADqi applying 
DSSMRq(psh. IDci. (ADci). 

2. H partitions, depending on the key size KS, the 
20 * lADci into different blocks BLj. 1 < i < P. with a length 

of 1 28 bits (P := flADci /KST). This ensures that the 
blocks to be included in each watermark are suffi- 
ciently small. 

3. H generates the stego image SI applying for 
25 every i. 1 < i ^ P, using the transformation: 

OIAE(crh(psH) XOR crh(i), BLj, Clj. SI;), 

where Clj denotes the cover Image (stego image 
30 from the previous iteration, Cli := CI) and SI} 
denotes the stego image of iteration i. The resulting 
stego image is tiien SI := Sip Set CI* := SI. 

Phase 3 (generating public watermark): 

35 

[0027] H generates a public lADci applying 

DSSMRq(psh. CD, lADci).^ " 

40 with CD := "Copyright by"||H||TVP|| "All Rights 
Reserved". 

H again partitions, depending on the key size KS, the 
lADci into different blocks BLj, 1 ^ I ^ P, with a length of 
128 bits (P :=riADc|/KST). 
45 H generates the stego image SI applying for every i, 1 ^ 
I ^ P. the following transformation: 

OIAE(crh(vsH) XOR crh(i). BLj. Clj. Slj). 

50 where Clj is the cover image (stego image from the pre- 
vious iteration. Cl^ = CI*, with CI* from tiie previous 
phase) and Slj is the stego image of iteration i. The 
resulting stego image is St = Sip 



H stores the resulting stego Image SI and may generate 
a signed copyright certificate. 



55 Phase 4: 



5 Phase 1 : 
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Phase 5: 

H and B execute the following steps for the trading of 
copyright protected digital images: 

5 

1 . H and B execute 

AKAP(H, B, Khb. PSh. vsh. PCh, vch. pse. vsg. 

PCb. VCb) 

10 

for the generation of a shared symmetric session 
key Khb* 

2. B generates the trading transaction T1 , 

T1 := <KHBn"D|iSigTD]>, with is 
TO := IDcil|TVP||B||H. and 
DSSAPg(PSb. TD SigTD). 

B then transmits T1 to H. 

3. H receives T1. deciphers KHBrD||SigTD]. and 20 
verifies TD, applying 

DSSAPv(vSb, SigTD, IVR) 

where IVR denotes the intermediate verification 25 
result. If 

IVR ^ crh(TD), with TD := IDcil|TVP||B||H. 

then TD has been successfully verified and the next 30 
step shall be executed. In any other case, the 
processing and communication between the H and 
B is stopped. 

4. H the verification was successful. H retrieves with 
the IDci information the corresponding stego image 35 
SI and generates the trading transaction 

T2 <KHB[TD||SigTD]>, with 

TD := SI ||TVP||H||B. and DSSAPqCPSh, TD 

SigTD). ' ' 40 

H then transmits T2 to B. 

5. B receives T2, deciphers KHB[TD||SigTD]. and 
verifies TD. applying 

45 

DSSAPv(vSh. SigTD. IVR), 

where IVR denotes the intermediate verification 
result. If IVR = crhfTD). with TD := SI||TVP||H||B. 
then TD has been successfully verified. B then so 
checks the IAD applying for every i, 1 :^ i < P. the fol- 
lowing transformation: 

OIAV(crh(vSH) XOR crh(i), SI. PLJ. 

55 

where Slj denotes the stego image and PLj the 
detected payload of the i-th public watermark. (If P 
is not known, the procedure is iteratively applied 



until no more public watermark can be detected). 
The lADci is then generated by concatenating the 
PLi. i.e. 

lADci := Pm|PL2||...||PLM.1<i<R 
lADc! is then verified applying 

DSSMRv(vSh, IADci.OD). 
with OD as the output data. If OD is 

"Copyright by"||H||TVP|| "All Rights Reserved", 

B has verified H as the copyright holder, if the public 
watermarks have not been modified (overwritten). 

Remark: 

[0028] In the case of a legal copyright dispute, H can 
retrieve the lADci and construct the corresponding 
unique image ID. Since the generation of the same 
asymmetric key pair by two distinguished entities is very 
unlikely the construction of the unique image ID pro- 
vides a good level of proof against copyright infringe- 
ment. In the case of watermark protection with 
registered keys, the generation of the same asymmetric 
key pair by two distinguished entities can be prevented. 
[0029] Depending on the applied asymmetric scheme 
the private decipherment key may be identical to the pri- 
vate signature key and the public encipherment key may 
be identical with the public verification key 

b) Watermark protection with registered keys: 

[0030] As shown in Fig. 2. the apparatus for the copy- 
right protection with registered cryptographic keys is 
partitioned into three processes, namely the ICH with 
the name H. the IB process with the name B. and the 
PKI process with the name L Suppose (psh.vsh). 
(PCh.vch). (PSb, vsb). (PCb, vcb), (ps|. vsj). and (pc,.vC|) 
are the unique elliptic curve key pairs of H, B, and I, 
respectively. Suppose H has an authentic and actual 
copy of CertB which signature was verified with the 
authentic copy of VS| and the B has an authentic and 
actual copy of Certn which signature was verified with 
the authentic copy of vs|. Then the same phases as for 
the individual watermark protection apparatus have to 
be applied. 

Remark: 

[0031 ] Since the generated asymmetric key pairs are 
unique, the ICH can be uniquely identified if no addi- 
tional watermarks by unauthorized persons have been 
encoded into the SI of the ICH. The ICO based water- 
mark protection provides the necessary counter meas- 
ures to prevent this threat. 
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c) ICO based watermark protection: 

[0032] As shown in Fig. 3, he apparatus for the iCO 
based watermark protection is partitioned into four proc- 
esses, namely the ICH wrth the name H, the IB process 5 
with the name B, the PKI process with the name I. and 
the ICO process with the name O. Suppose (psh.vsh). 

(PCh, VCh)^ (PSb.VSb), (PCb. VCb), (PS|.VS,) (pCi. VC|), (pSo. 

vSq). and (PCq-vCq) are the unique elliptic curve key 
pairs of H, B, I and O, respectively. H has an authentic w 
copy of Certe and Certo whose signatures were verified 
with the authentic copy of VS|. B has an authentic copy 
of CertH and Cert© whose signatures were verified with 
the authentic copy of vS|. and O has an authentic copy 
of Certn and CertB whose signatures were verified with is 
the authentic copy of vs|. 

[0033] The following phases are applied by the proc- 
esses of the ICO based copyright protection apparatus: 

Phase 1 to Phase 3: See Phase 1 to Phase 3 of the Indi- 20 
vidual watermark protection. 

Phase 4: 

H stores the resulting stego image SI. 25 
Phase 5: 

H and O execute the following steps for the secure reg- 
istration or validation of copyright requests, and the gen- 30 
eration of copyright certificates. 

1 . H and O execute 

AKAP(H, O, Kho. PSh. VSh, PCh, VCh. PSq, VSq. 55 
pCo VCo) 



step shall be executed. In any other case, the 
processing and communication between the H and 
O is stopped. O verifies the CRD with respect to 
legal copyright issues (uniqueness, originality, etc.). 
If the data has been successfully verified then the 
next step shall be executed. In any other case, the 
processing and communication between the H and 
O is stopped. 

4. If verification was successful. O generates the 
corresponding digital copyright certificate executing 

DSSAPg(PSo. CCD. SigCCD). 

O then stores the copyright certificate CC := 
CCD||SigCC and generates then the Copyright 
Confirmation Reply CCR 

CCR := <KHo[TD||SigTDl). with 

TD := CC||TVP||0||H. and DSSAPqCpsq, TD. 

SigTD). 

O then transmits CCR to H. 

5. H receives CCR. deciphers KHorD||SigTD], and 
verifies TD. applying 

DSSAPv(vSh. SigTD, IVR). 

where IVR denotes the intermediate verification 
result. If IVR = crh(TD). with TD := CC||TVP||01|H, 
then TD has been successfully verified. H then ver- 
ifies and stores the CC. 

The following phase can now be executed repeat- 
edly, if necessary, without repetition of the previous 
phases. 

Phase 6: 

H and B execute the following steps for the trading of 
copyright protected digital images: 

1 . H and B execute 

AKAP{H, B, Khb. PSh. vsh, PCh. vch. PSb, vSb, 
PCb, VCb) 

for the generation of a shared symmetric session 
key Khb. 

2. B generates the trading transaction T1 , 

T1 := <KHBlTD||SigTD] >, with 

TD := IDcillTVP||B||H. and DSSAPqCpSb, TD 

SigTD). 

B then transmits T1 to H. 

3. H receives T1, deciphers KHsFDIISigTD], and 
verifies TD, applying 

DSSAPv(vSb. SigTD, IVR) 



for the generation of a shared symmetric session 
key Khb- 

2. H retrieves the CRD and generates the copyright 40 
request CR, 

CR := <KHB[TD||SigTD]). with 

TD := CRD||TVP||H||0. and DSSAPqCpsh. TD. 

SigTD). 45 

H then transmits CR to O. 

3. O receives CR, deciphers KHB[TD||SigTD], and 
verifies TD. applying 



DSSAPv{vsh. SigTD. IVR) 



50 



where IVR denotes the intermediate verification 
result. If 

55 

IVR = crh(TD). with TD := CRD||TVP||H||0. 
then TD has been successfully verified and the next 
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where IVR denotes the intermediate verification 
result. If 

IVR = crh(TD), with TD := IDcil|TVP||B||H, 

5 

then TD has been successfully verified and the next 
step shall be executed. In any other case, the 
processing and communication between the H and 
B is stopped. 

4. tf the verification was successful, H retrieves with io 
the IDci information the corresponding stego image 

SI and generates the trading transaction 

T2 <KHBrD||SigTD]>, with 

TD := SI ||TVP||H||B. and DSSAPqCpsh, TD is 

SigTD). 

H then transmits T2 to B. 

5. B receives T2. deciphers KHBFDIISigTD], and 
verifies TD, applying 20 

DSSAPv(vsh. SigTD. IVR), 

where IVR denotes the intermediate verification 
result. If IVR = crhfTD), with TD := SI||TVP||H||B. 2S 
then TD has been successfully verified. B stores 
then the SI. 

Remark: 

30 

[0034] B may check the copyright certificate request- 
ing O to transfer an authentic copy of the copyright cer- 
tificate for a given image identifier IDc|. Except the data 
transferred, the applied protocol is the same as 
described in phase 4. 35 
[0035] If B would like to transfer a specific copyright of 
a CI to another legal party, he may initiate, a copyright 
revocation request with O. The different phases of this 
request are analogue to the copyright request. 
[0036] The method described in this section 11 40 
requires a suitable watermarking technique. Various 
such techniques are known and can be employed. How- 
ever, a prefen-ed technique is described in the next sec- 
tion. 

45 

III. Embedding the watermarks 

[0037] The watermarking technique described here 
comprises the following steps: 

50 

a) An en'or-control coding technique for the mes- 
sage to be transmitted in the watermark; 

b) A encoding technique to encode the message 
resulting from step a); 

c) A reliable method for embedding the encoded ss 
message from step b) in the image without intro- 
ducing visible artifacts. 



[0038] Each of these three aspects can be applied to 
conventional watermarking techniques. Preferably, they 
are used in combination to provide a highly reliable, 
robust and powerful method for marking data sets. This 
method can be applied for any watermarking applica- 
tions, in particular to the application described in section 
II of this disclosure. 

[0039] Steps a) and b) can be used for emt)edding 
watermarks in any type of data while step c) is opti- 
mized for embedding watermarks in images. 
[0040] In the following, the three elements of the 
watermarking technique are described in detail. 

Ill.a) Error control coding 

[0041 ] Error control coding is applied to the message 
prior to encoding step Ill.a). When used in combination 
with the procedure described in section II. the message 
corresponds to one of the blocks BLj. 
[0042] Preferably, symbol based Reed Solomon (RS) 
codes are applied for this purpose. The advantages are 
the following: 

RS codes correct symbol errors rather than bit 
errors, and 

RS codes can correct erasures as well as errors. 
Erasures can be factored out of the key equation, 
which means that "erased** symbols can be 
ignored. They do not play any role in the error con- 
trol mechanism - an erasure is useless redundancy. 

[0043] Being able to discard erased symbols has two 
advantages: 

If the posterior probability of a received symlx)l is 
low, it may be ignored. 
- ' ~RS codes only come in standard sizes. For exam- 
ple a 255 x 8 bit code is common. Most commonly 
used RS error control codes appear to be too large 
to be used in watermarking. However, it is possible 
to make almost any RS code fit a watermarking 
application by judiciously selecting symbols as 
being erased (because they were never embedded 
in the image in the first place). 

1 1 Lb) Encoding the message 

[0044] During encoding, the message to be transmit- 
ted in the watermark is transformed into a form suited 
for being used in the modulation of image components. 
At the same time, it is encrypted using a suitable key. 
[0045] If used with the method of section II. the encod- 
ing procedure has access to the cryptographic keys Ph 
and vh (or their hash values), which are applied as 
seeds to generate pseudo-random sequences as 
described below. The public key is used for encoding 
the message of the public watermark, the private key is 
used for the private watermark. Knowledge of the corre- 



9 



17 



EP 0 905 967 A1 



18 



spending key (or hash value) is required for recovering 
the message from the watermark. 
[0046] A watermark may be embedded or extracted by 
the key owner. In this form spread spectrum is a sym- 
metric key cryptosystem. From the point of view of 5 
embedding watermarks in images given the crypto- 
graphic keys the sequences themselves can be gener- 
ated. A good spread spectrum sequence is one which 
combines desirable statistical properties such as uni- 
formly low cross correlation with cryptographic security. io 
[0047] Suppose we are given a message B (e.g. that 
was provided with error coding in above step lll.a). The 
message has the binary form b-|b2. -bL. where bj are its 
bits. This can be written in the form of a set of symbols 
S1S2 . . .Sm ■ most generally by a change in a number is 
base from 2 to B. The next stage is to encode each sym- 
bol Sj in the form of a pseudo random vector of length N, 
wherein each element of this vector either takes the 
value 0 or 1 . N is e.g. in the order of 1 000 to 10000 (typ- 
ically in the order of 10% of the total number of image 20 
coefficients (Fourier components) that can. theoreti- 
cally, be modulated). 

[0048] in a preferred embodiment, this is carried out 
by using a pseudo random generator seeded by the key 
crh(pH) or crh(vH). 

[0049] To encode the first symbol a pseudo random 
sequence v of length N + B - 1 is generated. To encode 
a symbol of values where 0 < s < B the elements v^, Vg+i 
... Vs+N-1 are extracted as a vector of length N. For the 
next symbol another independent pseudo random 30 
sequence is generated and the symbol encoded as a 
random vector ¥2- Each successive synnbol is encoded 
in the same way. Note that even if the same symbol 
occurs in different positions in the sequence, no colli- 
sion is possible because the random sequences used to 3S 
encode them are different - in fact they are statistically 
independent. Finally the entire sequence of symbols is 
encoded as the summation: 

40 



[0050] The pseudo-random vector m has N elements, 
each varying between 0 and M. In a next step, the ele- 45 
ments of m are offset to make their mean zero. These 
elements will determine the strength of modulation of 
the Fourier components of the image in step lll.c. 
[0051] When decoding the watermark, a vector m' 
(read-out message) is derived from the stego-image. In so 
oblivious watermarking, m' corresponds to the modu- 
lated Fourier coefficients. Hence, in general m' will not 
be equal but "similar" to m. 

[0052] To decode s from m\ the elements of m' are 
first offset to make their mean zero. Then, starting from ss 
the (known) seed, the first random sequence v of length 
N + B - 1 is generated and the correlation of v with m' is 
calculated. The peak of the correlation indicates the off- 



set Si in the random sequence that was used for gener- 
ating fv Then, the next random sequence v is 
generated and cross-correlated with m' to retrieve S2. 
etc. 

[0053] Reliable communications of the apparatus are 
best accommodated by using m-sequences that pos- 
sess minimum cross correlation with each other. This is 
the same as maximizing the Euclidean distance 
between vectors v^, V2. V3... . 

[0054] If M is sufficiently large, the statistical distribu- 
tion of the message m should approach a Gaussian 
(Central Limit Theorem). A Gaussian distributed water- 
mark has the advantage that it is more difficult to detect. 
The variance increases with order M""^; in other words, 
the expected peak excursion of the sequence is only 
order M^^. 

lll.c) Embedding the message in the image 

[0055] In this step, the encoded message m (e.g. as 
obtained In the previous step) is applied to the image for 
generating the watermark. 

[0056] In contrast to steps lll.a) and lll.b), embedding 
the message in the image requires some knowledge of 
the nature of the data stored in the image. In the follow- 
ing, the image is assumed to be a two-dimensional 
image. The method is optimized for robustness against 
operations generally applied to images such as transla- 
tion, cropping, rotating, scaling. (The method is not opti- 
mized for other types of data, such as sound or text.) 
[0057] In order to achieve robustness against circular 
translation, the image block is first subjected to a Fou- 
rier transform. Then, message m is used to modulate 
the Fourier components. In addition to this, a template is 
embedded in the image, which tenplate can be used for 
detecting a rotation arxJ scaling of the image when read- 
ing the watermark. A tiling mechanism and suitable 
phase-dependent correction are applied for providing 
robustness against cropping. 

[0058] Figure 4 shows a detailed diagram describing 
the embedding of the watermark. Calculation starts 
from the cover image: 

1. If the image is a color image, then compute the 
luminance component (by replacing each pixel by 
g/2 + r/3 + b/6, where g, r and b are its green, red 
and blue components) and use these values for the 
following calculations. 

2. Divide the image into adjacent blocks of size 128 
X 128 pixels. 

3. IVlap the image luminance levels (or gray levels 
for a black and white image) because it conre- 
sponds to a perceptually "^lat" domain by replacing 
them with their logarithm. The logarithm is a good 
choice because it corresponds of the Weber-Fech- 
ner law which describes the response of the human 
visual system to changes of luminance. 

4. Compute the FFT (Fast Fourier Transform) of 
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each block. From the real and imaginary compo- 
nents obtained in this way, calculate corresponding 
magnitude and phase components. The magnitude 
components are translation invariant and will there- 
fore be used in the following modulation steps. 5 
(However, it is possit>le to derive translation invari- 
ants from the phase spectrum as well, which could 
also be modulated). 

5. Select the magnitude components to be modu- 
lated. To encode a message m of length N, a total 10 
number of N components are modulated. In non- 
oblivious watermarking, any components can be 
modulated. For oblivious watermarking, because of 
interference of the cover image with the watermark, 
the largest (highest energy) components (at about is 
the lowest 10% of the frequencies) are avoided and 
components at medium frequencies (about next 
30%) are used. These figures are chosen because 
they generally give a good compromise between 
robustness and visibility of the watermark. There 20 
are two methods for selecting the components to be 
modulated: 

a) The selection of the connponents to be mod- 
ulated does not depend on the given image. 25 
Rather, the same components are selected for 
every image. The author as well as the reader 

of the watermark know the positions of the 
components to be selected in advance. 

b) The largest components (inside the allowa- 30 
ble frequency range) are used for modulation. 

When selecting the components to be modulated, 
care must be taken to preserve the symmetry 
imposed on the Fourier components F(ki, k2) by ss 
the fact that the image block is real valued: 

F(ki,k2) = F*(Ni-ki,N2-k2) 
(where N^. N2 designate the size of the image 
block). Once the magnitude components (M^, „. 
Mm) to be modulated are chosen, the correspond- 40 
ing value m, of message m is added to or sub- 
tracted from the corresponding selected magnitude 
component Mj. Addition is used, if the correspond- 
ing phase component Pj is between 0 and n, sub- 
traction if it is between n and 2n. This provides 45 
robustness against translation and cropping (see 
below). 

Before adding/subtracting the values mj to/from Mj, 
the vector m can be scaled to adjust the magnitude 
of its elements to those of the components Mj. so 
Generally, the elements mj should be in the same 
order of magnitude as the components Mj. The 
depth of modulation or amplitude of the embedded 
signal should depend on the objective measure of 
the perceptual significance. The lower the percep- ss 
tual significance, the higher should be the ampli- 
tude of the watermark. However, for simplicity, the 
amplitude for all components is kept constant. 



6. Add a template by a second modulation of the 
magnitude components. This is described in more 
detail below. 

7. Compute the inverse FFT using the phase com- 
ponents and the modulated magnitude compo- 
nents. 

8. Compute the inverse of the perceptual mapping 
function of step 3. For Weber-Fechner law map- 
ping, the inverse function is an exponential. 

9. Replace each watermarked block in the image to 
obtain the stego image. 

10. tf the image is a color image, then rescale the 
red, green and blue components by the relative 
change in luminance introduced by embedding a 
watermark. Typically, the red, green and blue pixels 
occupy a byte each in program memory. If overflow 
or underflow occurs then the pixel is set to the 
upper bound 255 or lower bound 0 respectively. 

Template: 

[0059] As mentioned above, a template is added to 
the image in step 6. The steps for generating the tem- 
plate are illustrated in Fig. 5: 

20. Apply a log-polar map to the magnitude compo- 
nents, i.e. transform them into a polar coordinate 
system (©. log-r) with logarithmic radius axis. 

In this representation, a scaling of the image leads 
to an offset of the components along the log-r axis. 
A rotation of the image leads to an offset along the 
0 axis. 

Preferably, tow pass filtering is used for interpolat- 
ing the frequency space components during this 
mapping. 

The magnitude components belonging to very low 
or high frequencies are not mapped. The following 
modulation is only applied to components in 
medium frequency range. 

21 . Select the magnitude components in the log- 
polar coordinate system to be modulated. Typically, 
about 10% of all components are to be modulated. 
The pattern T formed by the selected components 
in log polar space should be such that its auto-cor- 
relation under translation is weak. For this purpose, 
the indices of the selected components should be 
coprime or be derived from a two-dimensional ran- 
dom sequence. 

Each selected component is increased by a given 
value. 

22. Map the modulated points by change of coordi- 
nates back into frequency space. 

[0060] The pattern T formed by the selected conrpo- 
nents in log polar space is predefined and known to the 
reader of the watermark. 

[0061 ] It must be noted that the calculation of the log- 
polar transform is not required for generating the tem- 
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plate. Instead of this, the pattern T of the components to 
be modulated in log-polar space can be mapped back to 
frequency space, which results in a pattern T in fre- 
quency space that can be applied directly to (e.g. added 
to) the components in frequency space. 5 
[0062] As will be explained below, the template is not 
required for non-oblivious watermarking. 
[0063] Figure 6 shows a detailed diagram illustrating 
the steps for reading a watermark from the stego image: 

10 

31. If the image is a color image then compute the 
luminance component and use these values for the 
following calculations. 

32. Divide the image into adjacent blocks of size 
128x128. '5 

33. Map the image luminance levels (or gray levels) 
to the perceptually "flat" domain by replacing them 
with their logarithm. 

34. For each block compute the FFT. 

35. Determine the rotation and scaling that the 20 
image suffered by finding the template in log-polar 
space. This is described below. 

36. Using the results of step 35, read the modulated 
components to generate message m'. This requires 
the knowledge of the method that was used in step 2s 
5 for selecting the components to be modulated. 

[0064] Once that the message m* is recovered, it is 
demodulated and error corrected using the methods 
described in sections lll.a) and lll.b). 30 

Finding the template: 

[0065] The steps for finding the template are illus- 
trated in Fig. 7: 35 

- 40. Apply log-polar mapping to the magnitude com- 
ponents of the Fourier transform. The magnitude 
conrponents belonging to very low or high frequen- 
cies are not mapped. The following analysis is only 40 
applied to components in medium frequency range 
41 . For ot^livious watermarking, calculate the nor- 
malized cross correlation of the components in log- 
polar space with the template pattern T that was 
used for generating the template in step 21 and find 45 
the point of best correlation. If the image has nei- 
ther been rotated or scaled, this point is at zero. 
Scaling leads to a corresponding offset along the 
log-r axis, rotation to a corresponding offset along 
the ® axis. 

For non-oblivious watermarking, the log polar trans- 
form of the Fourier components of the cover image 
can be used instead of template pattern T for 
retrieving scaling and rotation. 

The cross correlation can be calculated efficiently ss 
using conventional Fourier techniques. 



Properties of the watermark: 

[0066] In the following, some of the properties of the 
watermark generated using the steps described above 
are discussed. 

Resistance to cropping: 

[0067] One feature of translation invariants developed 
using the Fourier transform Is that they are invariant to 
circular translations (or cyclic shifts). This is used to 
construct watermarks that are invariant to cropping. 
This is illustrated by reference to Figs. 8 and 9. 
[0068] As mentioned above, the image is split into 
blocks and the watermark is applied to each block. In 
other words, the same modulation pattern is applied to 
the Fourier components of each block, wherein the 
modulation pattern is given by the corresponding 
encoded messages m. 

[0069] Fig. 8 shows such an image where the fat lines 
100 designate the borders between the blocks. Sup- 
pose that the watermark in a standard size block will be 
of the form: 

T=[A B : 0 D] 

where the submatrices A, B, C and D are of arbi- 
trary size. A circular translation of such a watermark is 
of the form: 

S=[D C : B A]. 

[0070] The original stego image is tiled with water- 
marks in the pattern [TTTT;TTTT;TTTT]. There- 
fore, a cropped section of the matrix will carry a 
watermark in the form [SSSS;SSSS;SSSS]. This 
is illustrated in Figure 9. When reading the watermark of 
the cropped image of Fig. 9, each block carries the 
watermark S. Since S is a circular transform of T, it can 
be read without problems in the Fourier domain using 
the steps outlined above. 

[0071 ] Note, however, that the cover image is not tiled, 
only the watermark is. Therefore, while cropping merely 
induces a circular translation of the watermark in each 
block, the change of image in each block is not a circular 
translation. To compensate for this, the phase compo- 
nents Pj of the Fourier transform must be used for cor- 
recting the sign of the modulation of the magnitude 
components Mj, as rt is outlined under step 5 above. 
[0072] The optimum size of block depends on a 
number of different factors. A size that Is a power of two 
is useful because the FFT can be used. The block size 
also must be small enough to withstand cropping but 
large enough to comfortably contain a watermark. The 
best compromise for block size is 128. 
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Resistance to scaling and rotation: 

[0073] As mentioned above, reading the template in 
log-polar space allows to detect and measure any scal- 
ing and/or rotation that was applied to the image. This 5 
information can then be used for reading the watermark. 
Since the reader knows the pattern that was used for 
modulating the magnitude components in step 5, he can 
identify the modulated components in the scaled and 
rotated Image and derive the message m' therefrom. io 
[0074] Note that the apparatus does not explicitly use 
a rotation and scale invariant watermark but instead 
searches the parameter space of rotations and scales. 
Since searching the space of rotation and scales in the 
frequency or space domain Is quite complicated, the is 
log -polar map is used where these parameters are Car- 
tesian coordinates and can be searched using efficient 
correlation techniques. 

Redundancy: 

[0075] The watermark Is embedded in blocks of a 
fixed size with exactly the same watermark embedded 
in each block. This means that the watermark can be 
recovered from a single block only. This leads to a ' 25 
redundancy that increases the chance of extracting the 
watermark correctly from more than one block. 

IV. Summary 

30 

[0076] The following summarizes some of the proper- 
ties of the preferred embodiments of the invention. 
[0077] The use of an asymmetric cryptographic key 
pair for the seed generation enables the execution of 
asymmetric key agreement protocols with message 35 
recovery or appendix and the protection of the commu- 
nication between the involved parties. Different security 
services for the communication, such as mutual authen- 
tication, integrity, confidentiality and non-repudiation are 
supported by the system with one asymmetric crypto- 40 
graphic key pair of the watermark author only for a reg- 
istration or trading process 

[0078] The present technique enables a strong bind- 
ing relation between the image ID, the image, and the 
ICH if the ICH registers his copyright at the ICO. If an 45 
image is watermarked later by an unauthorized person, 
the time stamp in the copyright certificates resolves the 
copyright ownership. 

[0079] The ICH does not have to reveal his private 
cryptographic key if ownership verification has to be so 
applied by a different legal party. 
[0080] The present technique supports transferral of 
copyrights. If copyright is transferred to another legal 
party, corresponding copyright revocation certificates 
may be generated. ss 
[0081] Digital signatures techniques are applied for 
the security of the communication between different 
parties and the authentication data embedded in a pri- 



vate or public watermark of an image. No signature 
labeling techniques of the complete image are applied 
by the system. 

[0082] The Fourier-Mellin transform has been 
enhanced as described above. The Fourier Mellin 
Transform is the Fourier Transform of a log polar map. In 
the present invention, the log polar map of a Fourier 
transform is used as a means of facilitating rotation cind 
seating invariance. 

[0083] Circular translation invariants are used as a 
means of constructing digital watermarks that are invar- 
iant to cropping. 

[0084] In contrast to some known techniques, the 
present system does not require a database of all 
watermarks that were ever embedded in image any- 
where. 

[0085] Information is embedded and/or retrieved in 
the log polar domain of the Fourier transform. Fre- 
quency components are modulated which are oblivious 
to the cover image but which also have the property that 
they form an unambiguous non-repeated pattern in log- 
polar space. They are used for determining the degree 
of rotation and scaling suffered by a stego-image in the 
absence of the cover-image. Coprime frequencies are 
useful for generating such a pattern or template. Uni- 
form random sampling of log polar space is another 
method that can be applied. 

[0086] The technique applies a new concept of invar- 
iants which are based on the modification of the well 
known FM transform and the coprime frequencies. 
[0087] TTie methods described above can be incorpo- 
rated into an apparatus, such as one or more comput- 
ers, using know programming and hardware 
techniques. To prove the feasibility of the approach, a 
Java based copyright protection and authentication 
environment for digital images has been implemented. 
The PKI, the ICH, the ICO, and the IB application proc- 
esses all innplement a Graphical User Interface and a 
server, supporting both console users and other 
requests through a socket interface. 

Claims 

1 . A method for generating and transmitting a data set 
between two parties H and B comprising the steps 
of 

a) providing a cover data set (CI) correspond- 
ing to the data set to be transmitted, 

b) generating a stego data set (SI) of said cover 
data set (CI) by embedding at least one digital 
watermark in said cover data set (CI), wherein 
said watermark is encoded using at least one 
key of an asymmetric cryptographic key pair 
(PSh, vsh) of H, said key pair comprising a 
secret private key (psn) and a known public key 
(vsh) derived therefrom, 

c) establishing a cryptographically secure 
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transmission between parties H and B with a 
key protocol using at least said key pair (psh. 
vSh) of H. 

d) transmitting said stego data set (SI) from 
said party H to said party B within said secure 5 
transmission. 

2. The method of daim 1 , wherein said cryptographi- 
cally secure transmission between said parties H 
and B is established using an asymmetric key pro- io 
tocol (AKAP{H,B.Khb.PSh.vsh.PSb.vsb)) based on 
said key pair (psn. vsh) of H and a private and pub- 
lic asymmetric cryptographic key pair (pse, vse) of 

B for generating a common key (Khb) between said 
parties H arxJ B. 15 

3. The method of one of the preceding claims wherein 
said key pair (psn. vsh) of H is an elliptic curve key 
pair. 

20 

4. The method of one of the preceding claims wherein 
said step b) further conprises the steps of 

generating at feast one private watermark, 
wherein said private watermark is encoded 2S 
using said private key (psh) of H, and prefera- 
bly also 

generating at least one public watermark, 
wherein said public watermark is encoded 
using said public key (vsh) of H. 30 

5. The method of claim 4 wherein said private water- 
mark is encoded using a hash value (crh(psH)) of 
said private key (psn) and can be decoded by using 
said hash value (crh(psH)). 55 

6. -The method of one of the preceding claims wherein 
said step b) comprises the step of generating at 
least one public watermark, wherein said public 
watermark is encoded using a hash value 4o 
(crh(vSH)) of said public key (vsh) of H, 

7. The method of one of the preceding claims wherein 
said step b) comprises the steps of 

45 

I) providing a message (Si, S2. .... s^) to be 
transmitted In said at least one watermarK said 
message consisting of a plurality of symbols, 
ii) providing a pseudo random generator 
seeded with a seed value derived from at least so 
one key of said key pair (psh, vsh) of H or a 
hash value thereof, 

III) encoding said message using values from 
said pseudo random generator. 

55 

8. The method of claims 7 wherein said step lil) com- 
prises 



for each of said symbols (sj), calculating a sym- 
bol vector (rj), wherein all elements of said vec- 
tor are derived from numbers from said pseudo 
random generator, 

adding said symtxjl vectors (fj) to generate an 
encoded message (m) and using said encoded 
message for embedding said watermark. 

9. The method of claim 8 wherein for each of said 
symbols (Sj) said pseudo random generator Is used 
for generating a pseudo random sequence of num- 
bers (vi , V2, ...). and wherein the value of said sym- 
bol (Sj) is used for selecting a sub-sequence within 
said pseudo random sequence for forming said 
symbol vector (rj). 

10. The method of one of the claims 8 or 9 comprising 
the following steps for decoding said watermark: 

extracting a read-out message (m*) from said 
watermarK said read-out message being a 
vector having the same length, if erased ele- 
ments are replaced by zero, as said symbol 
vectors (fj), 

generating all possible values of said symbol 
vectors (fj) using said pseudo random genera- 
tor seeded with said seed and calculating the 
correlation between all said possible values 
and said read-out message (m*). 

1 1 . The method of claims 9 and 1 0 comprising the step 
of calculating the cross-correlation between said 
pseudo random sequences of nunribers (v^. V2. ...) 
and said read-out message (m*) for retrieving said 
symbols (Sj). 

12. The method of one of the preceding claims com- 
prising the step of encoding a message for being 
embedded in said watermark by using symtK)l 
based Reed Solomon codes. 

13. The method of one of the preceding claims charac- 
terized in that said step b) further comprises the 
step of calculating a logarithm of said cover data set 
(CI) before embedding said watermark for embed- 
ding said watermark in a perceptually flat domain. 

14. Method for generating a stego data set (SI) of a 
cover data set (CI) especially for step b) of one of 
the preceding claims comprising the steps of 

generating at least one message (lADci). 
applying a digital signature to said message 
(lADci) using an asymmetric cryptographic key 
pair (Ph. vh). 

generating said stego data set (SI) of said 
cover data set (CI) by generating at least one 
digital watermark in said cover data set (CI), 
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wherein said watermark contains said mes- 
sage (lADci)- 

15. Method for generating and transmitting a data set 
between two parties H and B, especially oi one of 
the preceding claims, comprising the steps of 

providing a cover data set (CI) corresponding 
to the data set to be transmitted, 
generating a stego data set (SI) of said cover 
data set (CI) at a party H by generating at least 
one digital watermark in said cover data set 
(CI). 

transmitting said stego data set (SI) to a regis- 
tration party (O), and 

permanently storing certification data (CCD) at 
said registration party (O). said certification 
data comprising a hash value of said stego 
data set (SI), a digital time stamp (TVP) and 
information designating said party H. 

16. The method of daim 15 further comprising the 
steps of generating a digital signature of said certi- 
fication data (CCD) using an asymmetric crypto- 
graphic key pair (pso. vsq) of said registration party 
(O), transmitting said certification data (CCD) and 
said digital signature to said party H. and verifying 
said digital signature at said party H by using a pub- 
lic key (vsq) of said key pair of said registration 
party. 

17. Method for generating and verifying a watermark in 
a cover data set (CI) representing a cover image, 
especially for step b) of one of the preceding 
claims, comprising the following steps for generat- 
ing said watermark 

A) calculating the Fourier transform of at least 
part of said cover image for generating Fourier 
components of said cover image, and 

B) modulating at least part of said Fourier com- 
ponents using a template modulation pattern 
(T'). 

C) using the inverse Fourier transform for gen- 
erating a stego image. 

said method further comprising the following 
steps for verifying said watermark in a possibly 
scaled and/or rotated version of said stego 
image, 

D) calculating the Fourier transform of the pos- 
sibly scaled and/or rotated version of said 
stego image for generating Fourier compo- 
nents of said stego image. 

E) calculating a log-polar transform of said Fou- 
rier components of said stego image, and 

F) calculating the cross correlation between a 
log-polar transform (7) of said modulation pat- 
tern (T) and said log-polar transform of said 
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Fourier components of said stego image for 
evaluating a scaling and/or rotation factor. 

1 8. The method of claim 1 7 wherein said step B) further 
comprises the steps of 

calculating a log-polar transform of said com- 
ponents of said cover image for generating log- 
polar components, 

modulating said log polar components using a 
log-polar transform (T) of said modulation pat- 
tern (T), 

1 9. Method for generating a watermark in a cover data 
set (CI) representing a cover image especially for 
one of the preceding claims, characterized by the 
step of dividing said image into a plurality of adja- 
cent blocks and by the following steps carried out 
for each block: 

calculating the Fourier transform of the block of 
the block, and 

modulating at least part of the magnitude com- 
ponents of the Fourier transform of the block 
using a modulation pattern, wherein the same 
modulation pattern is used for all blocks. 

20. The method of claim 19, wherein the modulation 
pattern determines values to be added and/or sub- 
tracted for each of said magnitude components and 
wherein, at each frequency, the corresponding 
phase component of the Fourier transform is used 
for determining if said value is to be added or sub- 
tracted from said magnitude component. 
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The Search Division considers that the present European patent application does not comply with the 
requirements of unity of invention and relates to several inventions or groups of inventions, namely: 

1. Claims: 1-14 

Method for embedding a digital watermark in a data set using 
at least one of an asynfinetric cryptographic key pair 



2. Claims: 15,16 

Method for generating a digital waterinark in a data set, for 
transmitting that to a registration party and for 
certification data there 



3. Claims: 17-20 

Method for generating a watermark in a data set con^jrising 
calculating the Fourier transform of part of the data set 
and modulating part o 
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